CyberRota Analysis
AI-GeneratedFooocus image generating software versions 2.5.5 and earlier are critically vulnerable to remote code execution due to the insecure handling of metadata JSON via the eval function in the web UI. This flaw allows an attacker with access to the web interface to execute arbitrary code on the affected instance. Organizations using Fooocus should prioritize addressing this vulnerability, as no patched versions are currently available, and immediate mitigation measures are recommended.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.